TLP:WHITE132 IOCs
ClickFix Campaigns Targeting Windows and macOS
Threat Actors
Malware Families
Diamond Model
Adversary(1)
Infrastructure(6)
Capability(4)
Victim
5W+H Threat Analysis
Analysis unavailable
Indicators of Compromise
Indicators of Compromise132
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| SHA256 | 5d821db386c7c879caeabf3e9f94c94a48eec6ec5a3a0efbae9d69da3f52c1db file-hashintel-blogmalware | Medium | 53 | Jun 3, 26 |
| Domain | bebirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | quiptly.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | acconthelpdesk.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 45.144.233.192 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 45.93.20.141 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | shopifyservercloud.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | anthonydee.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | hostmaster.extracareliving.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | fixbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | usbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | bancatangcode.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 91.202.233.206 intel-blogloadermalware | High | 58 | Jun 3, 26 |
| Domain | octopox.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | 4freepics.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | extracareliving.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | topbirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 152.89.244.70 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | helpbirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | cryptoinfnews.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| URL | https://alababababa.cloud/cVGvQio6.txt. intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | mac-os-helper.com exploitintel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | mybirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macapp-apple.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | checkpulse.com exploitintel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | valetfortesla.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | suedfactoring.it.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | traderslinkfx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macosxapp.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | usebirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrepbiz.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | optbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | cryptonews-info.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | guypinions.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | gobirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | account-help.info intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankfx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankusa.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | getbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 193.58.122.97 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | sign-in-op-token.com intel-blogloadermalware | High | 58 | Jun 3, 26 |
| SHA256 | c0af6e9d848ada3839811bf33eeb982e6c207e4c40010418e0185283cd5cff50 file-hashintel-blogmalware | Medium | 53 | Jun 3, 26 |
| Domain | ustazazharidrus.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macosxappstore.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | appmacintosh.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 193.35.17.12 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | nowbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdreplab.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | thepulseactivity.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | appsmacosx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankinc.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | account-helpdesk.icu intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | appmacosx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macosx-apps.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | deinhealthcoach.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | accountpulse.help intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 193.222.99.212 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 62.164.177.230 c2intel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | birdrankzen.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | cryptoinfo-allnews.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | theinvestworthy.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | ms-scedg.com exploitintel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | mrinmay.net intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | gologpoint.com c2intel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | admin-activitycheck.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | justbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | customblindinstall.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | topbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrepgo.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | chrm-srv.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | vipbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | surecomforts.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macapps-apple.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankus.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | financementure.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | checkaccountactivity.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| SHA256 | 43907e54cf3d1258f695d1112759b5457576481072cc76a679b8477cfeb3db87 file-hashintel-blogmalware | Medium | 53 | Jun 3, 26 |
| IP | 94.156.112.115 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | nobovcs.com intel-blogloadermalware | High | 58 | Jun 3, 26 |
| Domain | yvngvualr.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | acebirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 77.91.65.31 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | bitbirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | helpdeskpulse.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macosx-app.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrepsys.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 77.91.65.144 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | fomomforhealth.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | hotelupdatesys.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankup.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | billiardinstitute.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | grandmastertraders.traderslinkfx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankbox.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | helpbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | ned.coveney-ltd.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macxapp.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | visitbundala.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | apposx.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| SHA256 | b17c3e4058aacdcc36b18858d128d6b3058e0ea607a4dc59eb95b18b7c6acc7c exploitfile-hashintel-blog | Medium | 53 | Jun 3, 26 |
| Domain | elive777a.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | orkneygateway.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrepusa.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | ariciversontile.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | pulse-help-desk.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | nhacaired88.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| SHA256 | 397dcea810f733494dbe307c91286d08f87f64aebbee787706fe6561ed3e20f8 file-hashintel-blogmalware | Medium | 53 | Jun 3, 26 |
| Domain | birdrephelp.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | account-helpdesk.top intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | bkng-updt.com intel-blogloadermalware | High | 58 | Jun 3, 26 |
| Domain | macxapp.org intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | bitbirdrank.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 87.236.16.20 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | account-helpdesk.info intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | appxmacos.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankvip.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | macosapp-apple.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | accountmime.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankllc.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | infobirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | joeyapple.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | checkpulses.com exploitintel-blogmalware | High | 58 | Jun 3, 26 |
| Domain | birdrepuse.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdranktip.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankgo.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | probirdrep.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| IP | 45.93.20.50 intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | checkhelpdesk.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | cryptoinfo-news.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | birdrankmax.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | elive123go.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
| Domain | thestayreserve.com intel-blogloadermalware | High | 58 | Jun 3, 26 |
| Domain | subsgod.com intel-blogmalwarenetwork | High | 58 | Jun 3, 26 |
IOC Relationship Graph
IOC Relationship Graph132 total IOCs
SHA256DomainIPURL